microtica agents
Docs menu

The Investigator in Slack

The Investigator works in your Slack the way a teammate would. Mention @Microtica with a question, and it acknowledges in a thread, digs through the connected accounts, and reports back in the same thread with what it found and how sure it is. Every case it opens also lives in the console, one click away — this page is how Microtica Agents feels day to day.

Summon it with a question

Mention @Microtica anywhere in a channel, with the question in the same message:

@Microtica why is checkout latency up since this morning?

The Investigator replies in a thread with a short acknowledgment and an Open case button, then investigates. When it finishes, the case lands in the same thread: a headline, the evidence, and a plain-language confidence phrase — “confirmed”, “likely, not confirmed”, or “low confidence” — so you always know how much weight to put on it. On your first summon in a channel it also joins the channel, so it can see later replies.

Point it at an alert

When a monitoring tool posts an alert, mention @Microtica in the thread under that post. The Investigator reads the alert message as the subject of the investigation, checks what changed recently, and reports back in the alert’s own thread. Mentioning it under any message works the same way — the parent message becomes the context.

If your project has several AWS or Kubernetes connections and the channel isn’t bound to one, the Investigator declines and asks you to bind the channel in Slack settings first — it never guesses which account you mean.

Continue in the thread

Replying in a case thread continues that investigation — no mention needed. The Investigator treats your reply as a follow-up on the same case, and it picks up any earlier replies it hadn’t processed yet, so nothing you typed gets lost. Mentioning @Microtica inside a case thread does the same thing.

The buttons on a case post

  • Open case — opens the case in the console, where the full journal lives.
  • Deepen — re-runs the investigation at full depth, chasing the open loose ends and data gaps. Use it when a first-pass answer isn’t enough.
  • Widen to <account> & continue — appears when an alert referenced another AWS account that’s connected to the project but outside the run’s scope. Clicking it approves the wider scope and continues the investigation. At most two of these appear.

Posts fired by a watch carry one more button — I fixed it — check — covered on the watches page.

The daily summon cap

Each project can start 20 new investigations from Slack per day; the count resets at midnight UTC. Follow-ups on existing cases are never capped — a human continuing a case is never rate-limited — and you can always start investigations from the console. When the cap is hit, the Investigator says so plainly instead of silently ignoring you. It’s equally honest when it can’t start for another reason, like the organization being out of credits.

Next: The inbox